
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0488 is a Missing Authorization (CWE-862) vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) that allows an authenticated attacker with low privileges to exploit a flaw in a generic function module call and execute unauthorized critical functionalities, including arbitrary SQL statements, resulting in full database compromise. The vulnerability was published on February 10, 2026, with a patch released on SAP's February 2026 Security Patch Day. Affected products include SAP WebClient UI Framework (versions 700, 701, 730, 731, 746, 747, 748, 800, 801), SAP S/4HANA (versions 102–109), and SAP NetWeaver Application Server ABAP 700. It carries a CVSS v3.1 base score of 9.9 (Critical) (Feedly, SAP Security Notes).
The root cause is CWE-862 (Missing Authorization): a generic function module call within the SAP CRM and S/4HANA Scripting Editor does not enforce proper authorization checks, allowing low-privileged authenticated users to invoke critical functionalities that should be restricted to administrators. An attacker with network access and valid (low-privilege) credentials can call this function module over the network without user interaction, passing arbitrary SQL statements that are executed directly against the underlying database. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself to the broader database and connected systems (Feedly, Onapsis Blog).
Successful exploitation leads to full database compromise with high impact on confidentiality, integrity, and availability. An attacker can read, modify, or delete sensitive business data stored in the SAP database, disrupt database operations, and potentially pivot to connected systems given the changed scope. Given that SAP CRM and S/4HANA typically store highly sensitive enterprise data (financial records, customer PII, supply chain data), the business impact of exploitation is severe (Feedly, SecurityOnline).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.039% (0.000390), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity, no user interaction requirement, and network-accessible attack vector make it an attractive target for threat actors once more details become public.
SAP released patches on February 11, 2026 as part of the February 2026 Security Patch Day; organizations should apply the relevant SAP Security Notes immediately via the SAP Support Portal. As interim mitigations, restrict access to the Scripting Editor functionality to only authorized administrative users, and implement strict role-based access controls to minimize the number of accounts that could be leveraged for exploitation. Monitor database and SAP audit logs for suspicious SQL execution patterns. Refer to SAP's official security patch documentation for specific note numbers and remediation steps (SAP Security Notes, Onapsis Blog, SecurityBridge).
The vulnerability received broad coverage across the security community following SAP's February 2026 Patch Day. Onapsis and SecurityBridge both published detailed patch day analyses highlighting CVE-2026-0488 as one of the most critical issues addressed (Onapsis Blog, SecurityBridge). SecurityOnline described it as a "critical SAP alert" with a CVSS 9.9 score exposing S/4HANA databases (SecurityOnline). Government CERTs including Ireland's NCSC, Belgium's CCB, and Canada's CCCS issued advisories urging prompt patching (NCSC Ireland, CCB Belgium, CCCS Canada). The Hacker News and GBHackers also covered the vulnerability as part of broader February 2026 Patch Tuesday reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."